WORDFENCE-eea99e1e-63c9-4021-80a0-1ed732b58ca9
medium
📛 Threat Title
Wp-ImageZoom < 1.0.5 - Directory Traversal
Description
The Wp-ImageZoom plugin for WordPress is vulnerable to Directory Traversal in versions before 1.0.5 via the 'file' parameter. This allows attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Affected software — plugin: Wp-ImageZoom (affected: [*, 1.0.5)). CVSS 5.3 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (1)
-
Wordfence remediation: Wp-ImageZoomWordfence
Update to version 1.0.5, or a newer patched version
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.